Location
San Francisco, CA, United States
Type
FULL TIME
Level
senior
Posted
Aug 18, 2026

Petual is the AI-powered control tester for the modern enterprise. We automate the most labor-intensive work in internal audit and governance: testing whether a company's financial, operational, and technology controls are effective as designed.

The hard part isn't exclusively speed of processing over a massive data set, it's also correctness. Our agents reason over messy, unstructured evidence screenshots, ledgers, ticket exports, and PDFs to reach a conclusion, and trace all reasoning to the source. When the evidence doesn't support a conclusion, we have to be precise about why, and what would need to be different to support a different outcome. External auditors re-perform our work, so "mostly accurate" means we’re failing.

We're backed by Andreessen Horowitz, First Round Capital, Cowboy Ventures, Elad Gil, and some of the best angel operators in the valley.

The Opportunity

We’re hiring a Security Lead to build and own the security function at Petual. You’ll inherit a strong technical baseline infrastructure as code, established cloud and app-security practices, an early compliance program from a team with roots at Retool and Lyft. From there, you’ll set the strategy, strengthen our posture, and take us through the compliance frameworks needed to serve regulated industries like banking and federal work.

What You’ll Do

Own Petual’s security strategy, roadmap, architecture, and day-to-day security program

Partner with engineering on application, cloud, infrastructure, and AI-system security

Advance vulnerability management, incident response, access governance, and detection evaluating tooling to drive leverage

Lead security reviews as a credible counterpart to enterprise customers

Own and evolve our compliance program as we pursue new frameworks

What We’re Looking For

Strong hands-on engineering. You write production code, and our interview loop includes a coding exercise

Experience securing enterprise SaaS handling sensitive data, ideally in fintech, GRC, or another regulated space

Experience with AWS, Kubernetes, and infrastructure as code

Experience securing AI-powered products or agentic systems

A track record taking a company through multiple stages of security maturity